Free guide:winning new clients predictably in 2026 · 10 pages, freeGet it now

AI governance for small teams: who may use which tool with which data

AI use at work rose from 59 to 75 per cent within a year, while the share of companies without a policy stayed at a third. Two thirds of AI access on corporate devices runs through personal accounts. What has been mandatory since February 2025, what providers actually do with your inputs, and what the rule looks like for a small team.

Cover: AI governance for small teams: who may use which tool with which data

AI has arrived in businesses, including small ones. According to the Statistics Austria press release of 24 June 2026, 30 per cent of Austrian companies with ten or more employees use AI technologies. Across the EU the figure is 20 per cent, in Germany 26, in Denmark 42. In Austria it was still 9 per cent in 2021, so the number has more than tripled in four years.

What has not grown alongside it: the answer to the question of who on the team may use which tool with which data. That is what AI governance means. The term sounds like a corporate department with a steering committee, but for a team of five to fifty people it means something very small: a mapping of data types to tools to named people. This piece covers what the evidence shows, what has actually been mandatory since February 2025, what providers really do with your inputs, and what that mapping looks like without anyone writing a twenty-page document.

Why is usage growing faster than the rules?

The Workplace Trend Report 2026 by SPS and the WORKTECH Academy measures both curves side by side. It surveyed 679 employees and managers across eight countries and eight industries, in the field from 23 January to 16 February 2026. The share of employees using AI tools in their daily work rose from 59 to 75 per cent within a year. The share of companies without a clear policy for it stayed practically unchanged: 32 per cent in 2025, 33 per cent in 2026.

Two values from the Workplace Trend Report 2026 side by side: the share of employees using AI in their daily work rose from 59 to 75 per cent within one year, while the share of companies without a clear AI policy stayed almost unchanged at 32 per cent in 2025 and 33 per cent in 2026.
Usage 59 per cent (2025) to 75 per cent (2026), a rise of 16 points. Companies without a clear AI policy 32 per cent (2025) to 33 per cent (2026), a rise of 1 point. Source: Workplace Trend Report 2026 by SPS and WORKTECH Academy, 679 employees and managers across eight countries and eight industries, fieldwork 23.01. to 16.02.2026, self-reported.

Where that usage goes when nobody maps it is measured by the Verizon Data Breach Investigations Report 2026 from May 2026. Two figures from it, summarised at Help Net Security: 45 per cent of employees are now regular AI users, against 15 per cent the year before. And 67 per cent of those accessing AI services on a corporate device do so through a non-corporate account. Shadow AI is now the third most common non-malicious insider action in the data-loss datasets analysed, a fourfold rise within a year. The single most common content type uploaded is source code.

The reflex at this point is to block. It does not work, because a personal account on a personal phone sits outside every block and the work still gets done faster. What does work is the more uncomfortable option: name the tools that exist, and name what may go into them. More on the pattern behind quiet parallel usage in the glossary entry on shadow AI.

What does the law already say, even for five people?

One duty has applied since 2 February 2025 and is regularly overlooked, because it does not look like compliance. Article 4 of the AI Act requires providers and deployers of AI systems to take measures to ensure, "to their best extent, a sufficient level of AI literacy of their staff". A deployer is anyone using an AI system in a professional capacity. An agency of eight people using ChatGPT for draft copy is a deployer. The duty attaches to the use, not to the size of the company.

Now the honest qualification, because it is missing from most write-ups: no direct fine is attached to this duty. Article 99(4) enumerates the sanctioned provisions one by one, naming Articles 16, 22, 23, 24, 26, 31, 33, 34 and 50. Article 4 is not among them. Anyone justifying governance purely with the threat of a penalty is arguing sloppily here. The reason to do it anyway is a different one: the literacy duty is the benchmark against which a team's competence gets judged if something goes wrong.

Data protection is firmer ground. As soon as personal data flows into an AI tool, meaning client names, job applications, email threads, the provider is processing on your behalf. Article 28(3) GDPR requires a contract for that, setting out "the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller". A personal account on a free plan does not have that contract. That is the real line between permitted and not permitted, and it does not run between providers, it runs between plans.

How far practice sits from either duty is shown by the Berlin Business Panel 2025, presented on 9 July 2026. Around 1,000 businesses were surveyed. 34 per cent of them work with AI technologies, well above the national average of 27 per cent. But of the businesses using AI, only 31 per cent offer any training on it, and only 26 per cent have a works agreement, a guideline or a written instruction on how to handle the technology.

Bar chart from the Berlin Business Panel 2025: 34 per cent of all Berlin businesses work with AI technologies against a national average of 27 per cent. Of the businesses using AI, only 31 per cent offer training and only 26 per cent have a works agreement, guideline or written instruction. The last two values refer to AI-using businesses, not to all businesses.
Berlin businesses using AI 34 per cent (national average 27 per cent, both as a share of all businesses). Of the AI-using businesses, 31 per cent offer training and 26 per cent have a works agreement, guideline or written instruction. Source: Berlin Business Panel 2025, Berlin Senate Department for Labour, Social Affairs, Equality, Integration, Diversity and Anti-Discrimination, around 1,000 businesses surveyed, presented on 09.07.2026. The literacy duty in Article 4 of the AI Act has applied since 02.02.2025.

Why does "we use AI" say nothing about your data?

Because the rule does not attach to the provider. It attaches to the plan, to a setting and to the subprocessors. Three verified examples, as of August 2026, all three readable in the providers' own help pages.

The Gemini app on a consumer plan. Google writes it plainly in the Gemini Apps help: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services." A subset of conversations is read by human reviewers, and those reviewed conversations are retained for up to three years even after you delete them from your account. Turn activity off and you land at 72 hours of retention.

Microsoft 365 Copilot on a business plan. Microsoft's documentation, dated 9 July 2026, says the opposite: "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation LLMs." The same page carries a sentence that appears in no summary: "Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary." So if you need the EU data boundary, the thing to check is not the product but the model selection inside it.

Claude on a consumer plan. Anthropic states in its privacy help, dated 16 March 2026, that conversations on the Free, Pro and Max plans only go into training if you actively allow it, and that Incognito chats stay out regardless. Feedback you submit yourself is retained for up to five years.

Two verified tools compared: on the Gemini app consumer plan human reviewers read a subset of conversations, reviewed conversations are kept for up to three years, and Google explicitly advises against entering confidential information. On Microsoft 365 Copilot business plans prompts, responses and Graph data are not used to train foundation models, but Anthropic models as a subprocessor currently sit outside the EU data boundary.
Gemini app (consumer plan): human reviewers read a subset of conversations, reviewed conversations retained up to three years, 72 hours with activity turned off, explicit warning "don't enter confidential information". Microsoft 365 Copilot (business plan): prompts, responses and Graph data are not used to train foundation models, Anthropic models as a subprocessor currently outside the EU Data Boundary. Sources: Google Gemini Apps help and Microsoft Learn, dated 09.07.2026.

The lesson is not that one provider is better than the other. It is this: the sentence "we use AI" is not a statement about your data. Only the combination of tool, plan, setting and subprocessor is one. And that combination changes without anyone calling you.

What does a rule look like that a team of ten actually follows?

It fits on one page and has three columns: data type, permitted tools, accountable person. That is our editorial practice and not a measured method, but the reasoning holds up: a policy you would have to read before pasting a text does not get read. A table in which you look up your own data type does.

Three data types are enough to start. Open is everything already published or destined to be: blog drafts, job ads, research from public sources. Internal is everything that should not leave the building but concerns no individuals: pricing calculations, process descriptions, source code. Confidential is everything involving personal data or someone else's confidentiality: client records, applications, contracts, health data. Sorting things into those buckets is its own small exercise, described under data classification.

Two rules matter more than any list. First: for confidential data, only tools with a data processing agreement qualify, and that is never a personal account. Second: every approval has a name next to it. Not "the team decides", but one person who vets new tools and maintains the table. Without that name the table goes stale within a quarter, because provider defaults move faster than anyone's attention.

How do you vet a new tool in ten minutes?

Four questions, in this order, answerable from the provider's own help pages:

1. Which plan is in play? Consumer or business. Almost every answer below hangs on that, not on the product name.

2. What is the default for training? Not what is possible, but what applies if nobody changes a setting. The answer differs per provider and it moves, as the example above dated 16 March 2026 shows.

3. Is there a data processing agreement and a list of subprocessors? The second half of that question is the more important one. A tool can sit in the EU itself and still call a model that does not.

4. How long is data retained and how do you delete it? Separately for ordinary history and for reviewed content. The second figure is routinely the larger one.

Writing those four answers into the tool table gives you more governance than the 74 per cent of AI-using businesses in the Berlin panel that have no guideline at all. And considerably more than a policy nobody opens. What belongs on the technical side once AI stops reading along and starts acting is covered under guardrails. When you have to label AI output, now that Article 50 became applicable in August 2026, we wrote up in The team page as a sales page.

The three levers

1. Write the tool table before you buy the next tool. Three columns, three data types, one name per row. An hour of work, and it answers the question everyone else answers quietly on their own.

2. Discharge the literacy duty visibly. Article 4 does not ask for certificates, it asks for measures. One documented hour with the team going through the four vetting questions and three real examples from your own week does more of that than a signed declaration.

3. Put a date on the table. Once a quarter, re-read the defaults of the tools in use and refresh the date. If nothing changed, that takes ten minutes. If something changed, you noticed it before your client did.

If you want to know which tools are actually circulating in your team and which of them stand on solid ground, we are happy to sort that out with you. 🧭